Critical Vulnerability with cPanel & WHM Login Authentication
Incident Lifecycle
Incident Timeline
Identified
Updates are now available for these build:
11.110.0.97
11.118.0.63
11.126.0.54
11.132.0.29
11.136.0.5
11.134.0.20
WP Squared 11.136.1.7
Please run the following command to retrieve the patched version.
/scripts/upcp --force
You can confirm you are on a patched version of cPanel with the following command:
/usr/local/cpanel/cpanel -V
As long as the output matches one of the above versions, then your system has been patched.
Warning: If your server is not running a supported version o...
11.110.0.97
11.118.0.63
11.126.0.54
11.132.0.29
11.136.0.5
11.134.0.20
WP Squared 11.136.1.7
Please run the following command to retrieve the patched version.
/scripts/upcp --force
You can confirm you are on a patched version of cPanel with the following command:
/usr/local/cpanel/cpanel -V
As long as the output matches one of the above versions, then your system has been patched.
Warning: If your server is not running a supported version o...
Apr 29, 2026 at 4:07 PM UTC
Identified
Updates are available:
TIER 11.110 WAS: 11.110.0.96 NOW: 11.110.0.97
TIER 11.118 WAS: 11.118.0.61 NOW: 11.118.0.63
TIER 11.126 WAS: 11.126.0.53 NOW: 11.126.0.54
TIER 11.132 WAS: 11.132.0.27 NOW: 11.132.0.29
TIER 11.134 WAS: 11.134.0.19 NOW: 11.134.0.20
TIER 11.136 WAS: 11.136.0.4. NOW: 11.136.0.5
Please run the following command to retrieve the patched version.
/scripts/upcp
* Webhosting Systems are being updated in stages, as they update cpanel s...
TIER 11.110 WAS: 11.110.0.96 NOW: 11.110.0.97
TIER 11.118 WAS: 11.118.0.61 NOW: 11.118.0.63
TIER 11.126 WAS: 11.126.0.53 NOW: 11.126.0.54
TIER 11.132 WAS: 11.132.0.27 NOW: 11.132.0.29
TIER 11.134 WAS: 11.134.0.19 NOW: 11.134.0.20
TIER 11.136 WAS: 11.136.0.4. NOW: 11.136.0.5
Please run the following command to retrieve the patched version.
/scripts/upcp
* Webhosting Systems are being updated in stages, as they update cpanel s...
Apr 28, 2026 at 11:36 PM UTC
Investigating
All cpanel/WHM VPS and Server owners please review: https://support.cpanel.net/hc/en-us/articles/40073787579671-Critical-Vulnerability-with-cPanel-WHM-Login-Authentication
At minumum
Disable cpdavd
whmapi1 configureservice service=cpdavd enabled=0 monitored=0
Then stop cpsrvd on your server:
/scripts/restartsrv_cpsrvd --stop
Please be aware cpanel/WHM services will be offline until a patch is released.
At minumum
Disable cpdavd
whmapi1 configureservice service=cpdavd enabled=0 monitored=0
Then stop cpsrvd on your server:
/scripts/restartsrv_cpsrvd --stop
Please be aware cpanel/WHM services will be offline until a patch is released.
Apr 28, 2026 at 8:45 PM UTC
Was your business affected by this InterServer outage?
Set up instant alerts for InterServer, be the first to know about outages via email, Slack, Teams, or Discord.